CVE-2002-1292

Microsoft Java Virtual Machine <= 5.0.3805 - Denial of Service via Security Manager Bypass

Title source: llm
STIX 2.1

Description

The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10585
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6133
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=103684360031565&w=2
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/237777
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103682630823080&w=2

Scores

EPSS 0.2245
EPSS Percentile 97.5%

Details

Status published
Products (1)
microsoft/java_virtual_machine 1.1
Published Nov 29, 2002
Tracked Since Feb 18, 2026